LWN.net Logo

tramp: insecure tmpfile creation

Package(s):tramp CVE #(s):CVE-2007-5377
Created:October 22, 2007 Updated:October 24, 2007
Description: From the Gentoo advisory:

A local attacker could create symbolic links in the directory where the temporary files are written, pointing to a valid file somewhere on the filesystem that is writable by the user running TRAMP. When TRAMP writes the temporary file, the target valid file would then be overwritten with the contents of the TRAMP temporary file.

Alerts:
Gentoo 200710-22 2007-10-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds